Bupa was unaffected by the cyber attack on recently purchased Australia-based Partnered Health Group, the insurer has said.
However, Partnered Health Group confirmed that personal information of its patients, including health information, had been stolen during the attack.
In June Bupa Australia announced the acquisition of healthcare service provider Partnered Health Group, subject to regulatory approval.
That same month, Partnered Health Group was victim to a cyber security incident affecting some of its systems.
Within its H1 2026 results statement published today, Bupa group confirmed no Bupa-held customer or employee data had been affected by the cyber security attack.
It said this was because the transaction had not yet completed and no systems have yet been integrated.
Cyber attack
According to an update on its website, Partnered Health confirmed that on 23 June 2026 it became aware that a malicious actor accessed some of its data.
In response, it said it engaged specialist cyber experts to provide advice and took immediate steps to contain the incident and assess whether personal information was accessed.
The provider noted that while this remained ongoing, investigations to date had confirmed personal information (including health information) was taken from some of the clinics in the firm’s network.
Partnered Health added it was continuing to investigate the extent to which personal information has been impacted by this incident and was communicating with patients from impacted clinics.
The firm said it sincerely apologised for any concern and inconvenience this may have caused its customers, confirming it had reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and law enforcement, and was continuing to work with the authorities.
A dedicated website page has also been set up with further information.
